PatchSiren

Dell CVE debriefs · Page 7

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM Dell CVE published 2026-06-22

CVE-2026-44273

CVE-2026-44273 is a Use of Default Credentials vulnerability in Dell Wyse Management Suite (WMS) versions prior to WMS 2605. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Information Disclosure. The vulnerability has a CVSS score of 6 and a severity of MEDIUM. Dell has provided a vendor advisory for mitigation. The CVE was published on 2026-06-22T20: [truncated]

HIGH Dell CVE published 2026-06-22

CVE-2026-44272

CVE-2026-44272 is a high-severity SQL injection vulnerability in Dell Wyse Management Suite (WMS) versions prior to WMS 2605. A low-privileged attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access. The vulnerability has a CVSS score of 8.8 and is considered HIGH severity. Dell has provided a vendor advisory for mitigation. The CVE was published on June 22 [truncated]

LOW Dell CVE published 2026-06-17

CVE-2026-35068

CVE-2026-35068 is an SQL injection vulnerability in Dell PowerFlex Manager versions prior to 5.1.0.1. A low-privileged attacker with adjacent network access could exploit it, leading to information disclosure. The vulnerability has a CVSS score of 3.5 and a severity of LOW. Organizations should review and apply patches to prevent potential information disclosure.

HIGH Dell CVE published 2026-06-17

CVE-2026-32652

CVE-2026-32652 is a 'Use of Default Credentials' vulnerability in Dell AIOps Collector versions prior to 1.18.3. A low privileged attacker with console access could potentially exploit this vulnerability to gain Filesystem access. This vulnerability only affects fresh installations of Collector versions earlier than 1.18.3. Systems that have been upgraded to version 1.18.3 or later are not impacted, even [truncated]

MEDIUM Dell CVE published 2026-06-17

CVE-2025-32748

CVE-2025-32748 is a medium-severity vulnerability in Dell PowerFlex rack, versions RCM 3.7/3.7. An unauthenticated attacker with remote access could potentially exploit this Host Header Injection vulnerability to trigger redirections. Organizations using affected versions should review and update their systems to mitigate potential risks. The CVSS score for this vulnerability is 4.3, indicating a medium s [truncated]

HIGH Dell CVE published 2026-06-17

CVE-2026-49502

CVE-2026-49502 is an Improper Authentication vulnerability in Dell PowerFlex Manager versions prior to 5.1.0.1. An unauthenticated attacker with adjacent network access could exploit this vulnerability, leading to information disclosure, tampering, and unauthorized access. The vulnerability has a high CVSS score of 7.4, indicating a high risk. Security teams should review and address this vulnerability promptly.

MEDIUM Dell CVE published 2026-06-17

CVE-2026-40641

CVE-2026-40641 is a Use of a Broken or Risky Cryptographic Algorithm vulnerability in Dell PowerFlex Manager versions prior to 5.1.0.1. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure and Information tampering. The vulnerability has a CVSS score of 4.8 and a severity rating of MEDIUM. The affected product is Dell PowerFlex Mana [truncated]

MEDIUM Dell CVE published 2026-06-17

CVE-2026-35067

Dell PowerFlex Manager versions prior to 5.1.0.1 contain an Improper Access Control vulnerability. A low-privileged attacker with adjacent network access could potentially exploit this vulnerability, leading to elevation of privileges and unauthorized access. This issue has a CVSS score of 5.7, indicating a medium severity level. The vulnerability allows attackers to gain unauthorized access and elevate p [truncated]

HIGH Dell CVE published 2026-06-17

CVE-2026-35066

CVE-2026-35066 is a HIGH-severity vulnerability in Dell PowerFlex Manager, with a CVSS score of 7.1. A low-privileged attacker with remote access could potentially exploit this Improper Access Control vulnerability, leading to a denial of service. The vulnerability was published on 2026-06-17 and modified on 2026-06-18. Dell has released a security update to address this issue. Organizations using affecte [truncated]

HIGH Dell CVE published 2026-06-17

CVE-2026-35065

CVE-2026-35065 is a high-severity vulnerability in Dell PowerFlex Manager versions prior to 5.1.0.1. The vulnerability allows an unauthenticated attacker with adjacent network access to potentially exploit it, leading to code execution, denial of service, information disclosure, information tampering, remote execution, script injection, and unauthorized access. This vulnerability is caused by a missing au [truncated]

HIGH Dell CVE published 2026-06-17

CVE-2026-32804

CVE-2026-32804 is a HIGH-severity vulnerability in Dell PowerFlex Manager, with a CVSS score of 8.1. It allows unauthenticated attackers with adjacent network access to gain unauthorized access. Dell has released a security update to address this issue. Organizations using affected versions should prioritize patching. The vulnerability was published on June 17, 2026, and updated on June 18, 2026.

HIGH Dell CVE published 2026-06-17

CVE-2026-22283

Dell PowerFlex Manager, versions prior to 5.1.0.1, are vulnerable to an Inclusion of Functionality from Untrusted Control Sphere vulnerability. This vulnerability allows an unauthenticated attacker with remote access to potentially exploit the vulnerability, leading to information disclosure. The affected product is Dell PowerFlex Manager. The vulnerability class is Inclusion of Functionality from Untrust [truncated]

HIGH Dell CVE published 2026-06-16

CVE-2024-39575

CVE-2024-39575 is a high-severity vulnerability with a CVSS score of 7.4. The vulnerability is related to the update_disk_psu_baseline.sh script, which requires a password in plain text. The CVE was published on 2026-06-16T19:16:29.040Z and last modified on 2026-06-16T20:41:35.520Z. The vendor is currently listed as Unknown Vendor, but evidence suggests a potential link to Dell [ref-4].

HIGH Dell CVE published 2026-06-16

CVE-2024-38487

CVE-2024-38487 is a HIGH severity vulnerability with a CVSS score of 7. The api-gateway container running with root privilege allows an attacker to escape the container and access the host system to perform unintended actions.

MEDIUM Dell CVE published 2026-06-16

CVE-2024-30476

CVE-2024-30476 is a Stored Cross-Site Scripting Vulnerability in the PowerStore Manager. A remote authenticated low-privileged malicious actor could potentially exploit this vulnerability, it could lead to script execution in the client browser. The vulnerability has a CVSS score of 5.4 and a severity of MEDIUM.

MEDIUM Dell CVE published 2026-06-16

CVE-2024-22451

CVE-2024-22451 is a MEDIUM-severity vulnerability in Dell Peripheral Manager, affecting versions from 1.5.1 to 1.7.2. The vulnerability is caused by an uncontrolled search path element, which could allow an attacker to preload a malicious executable, leading to arbitrary code execution. The CVSS score for this vulnerability is 6.7.

MEDIUM Dell CVE published 2026-06-16

CVE-2024-22447

CVE-2024-22447 is a MEDIUM-severity vulnerability in Dell Peripheral Manager, affecting versions prior to 1.7.3. The vulnerability is caused by an uncontrolled search path element, which could allow an attacker to execute arbitrary code by preloading malicious DLLs.

MEDIUM Dell CVE published 2026-06-09

CVE-2026-40639

CVE-2026-40639 is a MEDIUM-severity vulnerability in Dell Client Platform BIOS, with a CVSS score of 5.7. It involves Weak Encoding for Password, allowing an unauthenticated attacker with physical access to potentially exploit the vulnerability, leading to Elevation of Privileges.

MEDIUM Dell CVE published 2026-06-09

CVE-2026-44275

CVE-2026-44275 is a MEDIUM severity vulnerability in Dell/Alienware Purchased Apps versions prior to 1.1.32.0. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Arbitrary File Write. The vulnerability is caused by an Improper Link Resolution Before File Access ('Link Following').

MEDIUM Dell CVE published 2026-06-09

CVE-2026-41116

CVE-2026-41116 is a vulnerability in Dell Inventory Collector Client, versions prior to 13.8.0. The vulnerability is caused by an Improper Link Resolution Before File Access ('Link Following') issue. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Arbitrary File Write. The CVSS score for this vulnerability is 6.3, and the severity is classified as MEDIUM.

MEDIUM Dell CVE published 2026-06-09

CVE-2026-28262

CVE-2026-28262 is a MEDIUM-severity vulnerability in Dell iDRAC Tools, versions prior to 11.4.1.0. The vulnerability is caused by an Improper Link Resolution Before File Access ('Link Following') issue. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information tampering. The CVSS score for this vulnerability is 6. The CVE was published on 2026-06-09T0 [truncated]

HIGH Dell CVE published 2026-06-04

CVE-2025-46638

CVE-2025-46638 is a HIGH-severity vulnerability in Dell BSAFE SSL-J, which allows an unauthenticated remote attacker to potentially exploit the vulnerability, leading to a Denial of Service (DoS). The vulnerability has a CVSS score of 7.5 and was published on [cvePublishedAt](https://www.cve.org/CVERecord?id=CVE-2025-46638).

MEDIUM Dell CVE published 2026-05-22

CVE-2022-34363

Dell Unisphere for PowerMax Virtual Appliance versions prior to 10.0.0.2 contain an authorization bypass vulnerability in the Unisphere for VMAX application running within the vApp. The flaw, classified as CWE-285 (Improper Authorization), allows an authenticated attacker with low privileges to bypass authorization controls. The vulnerability has a network attack vector with low attack complexity, requiri [truncated]

MEDIUM Dell CVE published 2026-05-22

CVE-2022-31231

CVE-2022-31231 is an Improper Access Control vulnerability in the Identity and Access Management (IAM) module of Dell Elastic Cloud Storage (ECS), versions 3.5 and 3.6. This vulnerability allows a remote unauthenticated attacker to potentially gain read access to unauthorized data. The CVSS score for this vulnerability is 5.9, with a severity rating of MEDIUM. Organizations should prioritize patching this [truncated]

LOW Dell CVE published 2026-05-22

CVE-2025-46371

PatchSiren has analyzed CVE-2025-46371, a vulnerability in Dell PowerFlex Manager versions <= 4.6.2. The vulnerability is related to the use of a broken or risky cryptographic algorithm in SSH, potentially allowing a low-privileged attacker with local access to bypass protection mechanisms. This vulnerability has a CVSS score of 3.6, indicating a low severity. The vulnerability exists in the SSH component [truncated]

MEDIUM Dell CVE published 2026-05-22

CVE-2025-32751

CVE-2025-32751 is an Insecure Storage of Sensitive Information vulnerability in Dell PowerFlex Manager versions <= 4.6.2. A low-privileged attacker with local access could exploit this vulnerability, leading to unauthorized access to sensitive information. This vulnerability has a CVSS score of 5.5 and a severity rating of MEDIUM. System administrators and security teams should prioritize patching to prev [truncated]

MEDIUM Dell CVE published 2026-05-22

CVE-2021-21508

CVE-2021-21508 is a MEDIUM severity vulnerability in Dell VxRail Manager affecting versions before 7.0.200. A sys-admin user may exploit this vulnerability, leading to the disclosure of certain user credentials. The vulnerability has a CVSS score of 6.7 and a CVSS severity of MEDIUM. The vulnerability is caused by the storage of passwords in plain text, which can be exploited by a sys-admin user to gain u [truncated]

MEDIUM Dell CVE published 2026-05-22

CVE-2025-32749

CVE-2025-32749 is an Exposure of Information Through Directory Listing vulnerability in Dell PowerFlex Manager versions <=4.6.2. An unauthenticated attacker with remote access could exploit this, leading to information exposure. The vulnerability has a CVSS score of 5.3 and a severity of MEDIUM. Dell has provided mitigation guidance through their support documentation. Security teams and administrators of [truncated]

MEDIUM Dell CVE published 2026-05-22

CVE-2025-32747

CVE-2025-32747 is an Incorrect Privilege Assignment vulnerability in Dell PowerFlex Manager versions less than or equal to 4.6.2. A local attacker with low privileges could exploit this vulnerability to elevate their privileges. The vulnerability has a CVSS score of 5.3 and a severity rating of MEDIUM. System administrators and security teams responsible for Dell PowerFlex Manager installations, especiall [truncated]

MEDIUM Dell CVE published 2026-05-22

CVE-2025-32746

CVE-2025-32746 is an Insecure Storage of Sensitive Information vulnerability in Dell PowerFlex Manager versions less than or equal to 4.6.2. An unauthenticated attacker with local access could potentially exploit this vulnerability, leading to unauthorized access to sensitive information. This type of vulnerability typically allows attackers to access or manipulate sensitive data without proper authorizat [truncated]